Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP). The suspension went into effect on October 1, 2024, the day of the announcement. This decision does not affect product vulnerabilities submitted before this date, nor does it impact OSS VRP supply chain reports. Google indicated it might still accept reports for some Google Cloud repositories through the Cloud VRP.
The primary reason for the suspension is an influx of invalid bug reports driven by AI. The rise of large language models (LLMs) and automated AI bug-hunting scripts has significantly reduced the cost and effort required to generate bug reports, leading to a surge of low-effort, AI-generated submissions. These reports often claim to find bugs but are invalid or unexploitable hallucinations.
Google engineers and open-source maintainers were reportedly overwhelmed by thousands of these poorly written reports. They spent excessive time manually validating code that contained no actual vulnerabilities, diverting resources from fixing legitimate, critical security flaws. This inefficiency directly led to the program's suspension.
Similar issues have been observed across the tech industry. Linux maintainers reported being overwhelmed by CVE finds after AI-powered bug hunters increased the Linux kernel's vulnerability count to 2,000 per release. Intel also suspended its bug bounty program, with experts suspecting AI-generated reports as the cause, though the company did not officially confirm it. Google has committed to providing an update on its OSS VRP by the first quarter of 2027, indicating a period of reformatting and work on the program.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google has suspended its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerabilities, effective October 1, 2024. This action was taken due to an overwhelming number of invalid bug reports generated by AI, which burdened engineers and maintainers. The suspension highlights a growing challenge in cybersecurity as AI-driven tools generate false positives, impacting resource allocation for legitimate security work.